US2025141666A1PendingUtilityA1

System and method for encrypted disk inspection

Assignee: WIZ INCPriority: Dec 27, 2021Filed: Dec 27, 2024Published: May 1, 2025
Est. expiryDec 27, 2041(~15.4 yrs left)· nominal 20-yr term from priority
H04L 9/0894H04L 9/0825H04L 67/1097H04L 9/0822
55
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A system and method for inspecting encrypted disks for a cybersecurity object using a custom key is presented. The method includes detecting an encrypted disk associated with a workload in a cloud computing environment, the cloud computing environment including a security policy server; authorizing a key policy for decrypting the encrypted disk on the security policy server for a custom key associated with an inspector account; decrypting the encrypted disk with the custom key by the inspector account; and generating an inspectable disk based on the decrypted encrypted disk.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for inspecting encrypted disks for a cybersecurity object using a custom key, comprising:
 detecting an encrypted disk associated with a workload in a cloud computing environment, the cloud computing environment including a security policy server;   authorizing a key policy for decrypting the encrypted disk on the security policy server for a custom key associated with an inspector account;   decrypting the encrypted disk with the custom key by the inspector account; and   generating an inspectable disk based on the decrypted encrypted disk.   
     
     
         2 . The method of  claim 1 , further comprising:
 inspecting the inspectable disk to detect a cybersecurity object.   
     
     
         3 . The method of  claim 2 , further comprising:
 generating the inspectable disk based on a clone of the decrypted encrypted disk.   
     
     
         4 . The method of  claim 2 , further comprising:
 generating the inspectable disk based on a snapshot of the decrypted encrypted disk.   
     
     
         5 . The method of  claim 2 , further comprising:
 generating the inspectable disk based on a copy of the decrypted encrypted disk.   
     
     
         6 . The method of  claim 1 , further comprising:
 determining that the encrypted disk utilizes an application based encryption; and   fetching the custom key from a key vault management system.   
     
     
         7 . The method of  claim 1 , further comprising:
 decrypting the custom key, wherein the custom key is encrypted using a key-encryption-key.   
     
     
         8 . The method of  claim 1 , further comprising:
 setting a decoded base64 key from a key vault on the encrypted disk, in response to determining that an operating system of the workload utilizes Bitlocker.   
     
     
         9 . The method of  claim 1 , further comprising:
 determining that the encrypted disk is encrypted based on metadata associated with the encrypted disk.   
     
     
         10 . A non-transitory computer-readable medium storing a set of instructions for inspecting encrypted disks for a cybersecurity object using a custom key, the set of instructions comprising:
 one or more instructions that, when executed by one or more processing circuitries of a device, cause the device to:
 detect an encrypted disk associated with a workload in a cloud computing environment, the cloud computing environment including a security policy server; 
 authorize a key policy for decrypting the encrypted disk on the security policy server for a custom key associated with an inspector account; 
 decrypt the encrypted disk with the custom key by the inspector account; and 
 generate an inspectable disk based on the decrypted encrypted disk. 
   
     
     
         11 . A system for inspecting encrypted disks for a cybersecurity object using a custom key comprising:
 one or more processing circuitries configured to:   detect an encrypted disk associated with a workload in a cloud computing environment, the cloud computing environment including a security policy server;   authorize a key policy for decrypting the encrypted disk on the security policy server for a custom key associated with an inspector account;   decrypt the encrypted disk with the custom key by the inspector account; and   generate an inspectable disk based on the decrypted encrypted disk.   
     
     
         12 . The system of  claim 11 , wherein the one or more processing circuitries are further configured to:
 inspect the inspectable disk to detect a cybersecurity object.   
     
     
         13 . The system of  claim 12 , wherein the one or more processing circuitries are further configured to:
 generate the inspectable disk based on a clone of the decrypted encrypted disk.   
     
     
         14 . The system of  claim 12 , wherein the one or more processing circuitries are further configured to:
 generate the inspectable disk based on a snapshot of the decrypted encrypted disk.   
     
     
         15 . The system of  claim 12 , wherein the one or more processing circuitries are further configured to:
 generate the inspectable disk based on a copy of the decrypted encrypted disk.   
     
     
         16 . The system of  claim 11 , wherein the one or more processing circuitries are further configured to:
 determine that the encrypted disk utilizes an application based encryption; and   fetch the custom key from a key vault management system.   
     
     
         17 . The system of  claim 11 , wherein the one or more processing circuitries are further configured to:
 decrypt the custom key, wherein the custom key is encrypted using a key-encryption-key.   
     
     
         18 . The system of  claim 11 , wherein the one or more processing circuitries are further configured to:
 set a decoded base64 key from a key vault on the encrypted disk, in response to determining that an operating system of the workload utilizes Bitlocker.   
     
     
         19 . The system of  claim 11 , wherein the one or more processing circuitries are further configured to:
 determine that the encrypted disk is encrypted based on metadata associated with the encrypted disk.

Join the waitlist — get patent alerts

Track US2025141666A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.